Path Traversal Vulnerability in Altium Enterprise Server and Altium 365
CVE-2026-14439
What is CVE-2026-14439?
A path traversal vulnerability has been identified in the Git Service component utilized by both Altium Enterprise Server and Altium 365. This vulnerability arises from the service accepting user-supplied paths without proper validation during a sequence of post-clone file-manipulation operations. An authenticated user with basic git access can exploit this flaw to move files outside their designated repository area. This exploitation can lead to an attacker placing malicious scripts into directories where they can be executed by the service, resulting in remote code execution using the Git Service account. Especially concerning is the potential impact on multi-tenant Altium 365 deployments, where unauthorized access to data from other tenants could occur. Remediation has been implemented for version 8.1.1 of Altium Enterprise Server, and steps are underway to address this vulnerability across other Altium 365 deployments.
Affected Version(s)
Altium 365 Web <= unspecified
Altium Enterprise Server Web 0 < 8.1.1
